Show filters
323 Total Results
Displaying 291-300 of 323
Sort by:
Attacker Value
Unknown

CVE-2007-5635

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-4383

Disclosure Date: August 17, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in tracking.php in Trackeur 1 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: CVE and a third party dispute this vulnerability because header is defined before use. The researcher is known to be unreliable
0
Attacker Value
Unknown

CVE-2007-4305

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.
0
Attacker Value
Unknown

CVE-2007-2854

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.
0
Attacker Value
Unknown

CVE-2007-2819

Disclosure Date: May 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in reportItem.do in Track+ 3.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the projId parameter.
0
Attacker Value
Unknown

CVE-2007-2330

Disclosure Date: April 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
0
Attacker Value
Unknown

CVE-2006-7159

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.
0
Attacker Value
Unknown

CVE-2007-1046

Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.
0
Attacker Value
Unknown

CVE-2006-6972

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) by and (2) order parameters. NOTE: it is not clear whether this issue is exploitable.
0
Attacker Value
Unknown

CVE-2007-0347

Disclosure Date: January 29, 2007 (last updated October 04, 2023)
The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service (database error) via a ' character in certain messages, tickets, or Wiki entries.
0